Network security situation assessment method integrating fuzzy cluster analysis and fuzzy comprehensive evaluation decision-making

By integrating fuzzy clustering analysis and fuzzy comprehensive judgment decision-making methods, the flexibility and adaptability of network security situation awareness are solved, flexible response to dynamic changes in the network environment and timely discovery of new attacks are achieved, and the accuracy and reliability of network security situation evaluation are improved.

CN120342780BActive Publication Date: 2025-08-12CHENGDU UNIV OF INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510780752.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-08-12
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

Existing network security situation awareness methods cannot flexibly adapt to dynamic changes in the network environment, are difficult to cover unknown attacks and zero-day vulnerabilities, and are difficult to fully capture event correlation, resulting in the inability to discover new attacks in a timely manner.

Method used

The method of fusion fuzzy clustering analysis and fuzzy comprehensive judgment decision-making is adopted, and the data is standardized through the translation-extreme transformation method, the fuzzy similarity matrix and the fuzzy equivalent matrix are constructed, and the situation factor set is constructed dynamically. The weight is determined by hierarchical analysis method to conduct network security situation evaluation.

Benefits of technology

It realizes the flexibility and adaptability of network security situation assessment, can respond to threat changes in a timely manner, comprehensively consider the fuzzy interactions of various clustering factors, and improves the accuracy and reliability of the assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342780B_ABST
    Figure CN120342780B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security situation assessment method that integrates fuzzy cluster analysis and fuzzy comprehensive evaluation and decision-making, which relates to the field of network security technology. The method includes: first, obtaining an initial data matrix, then using the translation-range transformation method to standardize it, then constructing a fuzzy similarity matrix through the similarity coefficient-quantity product method, then obtaining a fuzzy equivalence matrix based on the closure transfer characteristic, and performing dynamic clustering to construct a first-level situation factor set and a second-level situation factor set; then, based on expert advice, obtaining a single-factor fuzzy mapping set of characteristic attributes of each cluster, and using the hierarchical analysis method to obtain the corresponding weight vector; using a weighted average operator to calculate the fuzzy comprehensive evaluation matrix, and then obtaining the status of the network security situation through the maximum membership principle. Therefore, the above method can comprehensively consider the fuzzy interactions and weight distribution of each clustering factor to achieve network security situation assessment, and the assessment framework is more flexible and adaptable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a network security situation assessment method integrating fuzzy cluster analysis and fuzzy comprehensive evaluation and decision-making. Background Art

[0002] As cybersecurity threats become increasingly complex and diverse, ensuring network security and stability has become a pressing task for social development. The importance of cybersecurity situational awareness has also become increasingly prominent. It is not only the cornerstone of maintaining network security, but also a key technology for enhancing network defense capabilities and ensuring network stability.

[0003] Currently, cybersecurity situational awareness plays an irreplaceable role in blocking potential security threats and optimizing defense strategies. However, the fixed nature and static definition of indicators in traditional models prevent them from flexibly adapting to the dynamic changes in the cybersecurity landscape and enabling timely adjustments to address emerging and unexpected security incidents. Furthermore, existing indicators have limited generalization capabilities, making it difficult to monitor for unknown attacks and zero-day vulnerabilities, resulting in an inability to provide effective early warning of new attacks. Furthermore, the complexity of cybersecurity incidents makes it difficult for current indicator systems to fully capture the correlations between events, thus failing to reveal deeper security threats.

[0004] Therefore, it is necessary to provide a network security situation assessment method that can flexibly respond to changes in the network environment, and quickly adjust the assessment indicators and analyze their correlation according to changes in threat intelligence to ensure that new threats can be discovered and responded to in a timely manner. Summary of the Invention

[0005] The purpose of the present invention is to provide a network security situation assessment method that integrates fuzzy cluster analysis and fuzzy comprehensive evaluation decision-making, which can effectively perform security situation assessment and has greater flexibility and adaptability.

[0006] To achieve the above objectives, the present invention provides a network security situation assessment method that integrates fuzzy cluster analysis and fuzzy comprehensive evaluation decision-making, comprising the following steps:

[0007] S1. Taking the characteristic attributes of different attack types as the first-level indicator domain and the attack type as the second-level indicator trait, we can obtain the initial data matrix.

[0008] S2. Use the translation-range transformation method to standardize the initial data matrix, and based on the standardized matrix, obtain the similarity measure of each pair of feature attributes through the similarity coefficient-scalar product method, and then construct the fuzzy similarity matrix;

[0009] S3. Based on closure transfer, the fuzzy similarity matrix is used to obtain the fuzzy equivalence matrix, and the threshold is set by analyzing the fuzzy equivalence matrix to perform dynamic clustering, thereby constructing the first-level situation factor set and the second-level situation factor set;

[0010] S4. Abstract the cybersecurity situation assessment scenario into a judgment set, and perform single-factor judgment on the characteristic attributes of the secondary situation factor set to obtain a single-factor fuzzy mapping set of characteristic attributes for each cluster;

[0011] S5. Using the analytic hierarchy process, respectively, obtain the judgment matrices of the first-level situation factor set and the second-level situation factor set, and obtain the corresponding weight vectors according to the judgment matrices;

[0012] S6. Use the weighted average operator to calculate the fuzzy comprehensive evaluation matrix, and then obtain the situation value through the maximum membership principle, and then obtain the status of the network security situation.

[0013] Preferably, a fuzzy similarity matrix is constructed, and the formula is as follows:

[0014] ;

[0015] in, , For the The characteristic attribute and The similarity of the feature attributes, 、 Respectively The first attack type Feature attributes, The first attack type feature attributes.

[0016] Preferably, dynamic clustering will be the first-level indicator domain Divide ,in is the number of classes in dynamic clustering, and , ;

[0017] The collection of clusters is the first-level situation factor set, and the characteristic attribute set in each cluster , is the set of secondary situation factors, where .

[0018] Preferably, obtaining the fuzzy equivalence matrix includes using the fuzzy similarity matrix and sequentially obtaining the quadratic value, as follows:

[0019] ;

[0020] in, is the fuzzy similarity matrix, when = hour, It is the fuzzy equivalence matrix.

[0021] Optimally, the single factor fuzzy mapping set is used to map the secondary situation factor set based on the advice and experience of network security experts. of The characteristic attributes of each cluster are judged by single factors, and then the characteristic attributes of each cluster are judged for the network security situation The membership degree of each element Assign values to obtain the single-factor fuzzy mapping set of characteristic attributes of each cluster , and then obtain the characteristic attribute single factor evaluation matrix of each cluster .

[0022] Preferably, the fuzzy comprehensive evaluation matrix is calculated as follows:

[0023] Let the secondary situation factor set The corresponding weight vector is , using the average weighted operator and Calculate and obtain the comprehensive evaluation matrix of the characteristic attributes in each cluster:

[0024] , ;

[0025] Where, represents the average weighted operator;

[0026] The comprehensive evaluation matrix of the characteristic attributes in each cluster is combined to obtain the total evaluation matrix:

[0027] ;

[0028] Similarly, let the first-level situation factor set The weight vector is , and then use the average weighted operator to obtain the comprehensive evaluation matrix.

[0029] Preferably, the maximum membership principle includes The situation value with the highest membership is selected to minimize the fuzziness and uncertainty of situation assessment, thereby understanding the status of network security situation.

[0030] Therefore, the present invention adopts the above-mentioned network security situation assessment method integrating fuzzy cluster analysis and fuzzy comprehensive evaluation decision, which has the following technical effects:

[0031] (1) Fuzzy cluster analysis is used to dynamically cluster the characteristic attributes of various network attacks, thereby constructing a set of first-level situation factors and a set of second-level situation factors, making the evaluation framework more flexible and adaptable.

[0032] (2) Apply fuzzy comprehensive evaluation decision-making technology, comprehensively consider the fuzzy interaction and weight distribution of each clustering factor, and determine the weight of each indicator through hierarchical analysis method to ensure the validity and reliability of the evaluation results, thereby realizing network security situation assessment.

[0033] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 1. It is a schematic diagram of fuzzy cluster analysis in an embodiment of a network security situation assessment method integrating fuzzy cluster analysis and fuzzy comprehensive evaluation and decision-making;

[0035] Figure 2 It is a schematic diagram of a fuzzy equivalent matrix construction model in an embodiment of a network security situation assessment method integrating fuzzy clustering analysis and fuzzy comprehensive evaluation and decision-making;

[0036] Figure 3 1. It is a schematic diagram of fuzzy comprehensive evaluation and decision-making in an embodiment of a network security situation assessment method integrating fuzzy cluster analysis and fuzzy comprehensive evaluation and decision-making;

[0037] Figure 4 It is a fuzzy equivalence relationship heat map in an embodiment of a network security situation assessment method integrating fuzzy cluster analysis and fuzzy comprehensive evaluation decision;

[0038] Figure 5 It is a dynamic cluster analysis diagram in an embodiment of a network security situation assessment method that integrates fuzzy cluster analysis and fuzzy comprehensive evaluation and decision-making. DETAILED DESCRIPTION

[0039] The present invention can be explained in more detail by the following examples. The purpose of disclosing the present invention is to protect all changes and improvements within the scope of the present invention. The present invention is not limited to the following examples.

[0040] The current network environment is becoming increasingly complex, and the emergence of diverse network attack methods poses a major challenge to network security situation awareness. Understanding and analyzing the characteristic attributes of these network attacks is crucial to maintaining network security. These characteristic attributes (such as the amount of data flowing into the node, transmission delay, transmission rate, etc.) are key indicators that describe the characteristics of network nodes or connections. Based on this, this embodiment uses fuzzy clustering analysis to systematically classify these attributes, which helps to identify the internal connections and differences between different attributes, thereby improving the accuracy and reliability of network security situation assessment. Figure 1shown.

[0041] Fuzzy cluster analysis, a highly adaptable data processing technique, allows for fuzzy affiliation of data points, meaning that a single data point can be simultaneously assigned to multiple categories. This flexibility is particularly useful for processing cybersecurity data with overlapping characteristics, as the characteristic attributes of cyberattacks are often complex and intertwined, making it difficult to assign them to a single, clear category. Fuzzy clustering methods can provide insight into the commonalities and differences between different types of cyberattacks, providing a new perspective and technical approach for cybersecurity situation assessment.

[0042] In this embodiment, an in-depth fuzzy clustering analysis was conducted on the NUSW-NB15 dataset as the research object, which contains seven key characteristic attributes of nine types of network attacks, as shown in Table 1.

[0043] Table 1 Description of attack types and their characteristic attributes in the NUSW-NB15 dataset

[0044] ;

[0045] like Figure 2 As shown, by constructing a fuzzy equivalence matrix, the similarity and mutual correlation between objects or variables are quantified and revealed, thereby analyzing the potential correlation between the characteristic attributes of different attack types. It describes the connection between different entities through a numerical method, thus providing a quantitative interaction perspective. In this embodiment, the characteristic attributes of different attacks in the network environment are abstracted as research objects, and the similarity between these characteristic attributes is numerically quantified with the help of the fuzzy equivalence matrix, which provides an effective way to construct the first-level and second-level network situation factor sets. It can also conduct a detailed assessment of the correlation and linkage between the characteristic attributes of different attacks, thereby providing a more accurate benchmark for the calculation of the situation value of the network security situation, as follows:

[0046] (1) Matrix initialization: taking the characteristic attributes of different attacks as the domain The elements in are set as the first-level indicator domain, and the attack type is used as its second-level indicator trait, which is set as , In this embodiment, , Based on this, an initial data matrix consisting of feature attributes and attack types is constructed as follows:

[0047] .

[0048] (2) Data standardization: In order to ensure that the various characteristic attributes of the network security situation can be objectively processed and analyzed in the fuzzy cluster analysis, the "translation-range transformation method" is used to standardize the initial matrix composed of characteristic attributes and attack types. This method not only ensures that the data follows the established standard distribution by reasonably translating and scaling the data, but also ensures that different measurement dimensions, such as attack duration, data inflow, data transmission rate, and network bandwidth, can have similar measurement scales in the analysis, thereby reducing the result deviation and improving the accuracy and reliability of cluster analysis.

[0049] (3) Establish a fuzzy similarity matrix: Each characteristic attribute in the standardized matrix can be regarded as a feature vector, whose dimension is consistent with the number of attack types involved. The value of each element in the feature vector shows the representation of the network characteristics under various attack conditions.

[0050] By calculating the scalar product between the eigenvectors, we can measure their similarity, which reflects the degree of similarity between the two vectors in each dimension. The larger the scalar product, the higher the similarity. Specifically, for the matrix after standardization, the "similarity coefficient-scalar product method" is used to form a fuzzy similarity matrix with the similarity measurement results between each pair of feature attributes. The elements of this matrix are express and The degree of similarity between them is expressed as follows:

[0051] ;

[0052] in, .

[0053] (4) Closure transitivity: Similarity metrics are usually used to compare the degree of similarity between two objects. When there are multiple objects to be compared, similarity matrices can be constructed to represent the similarity relationships between them. However, these similarity relationships may not be transitive, that is, if the objects with objects Similarity, object with objects Similar, but not necessarily the same object with objects They must be similar, which requires the use of closure transfer to handle them.

[0054] In this embodiment, the fuzzy similarity matrix formed by the similarity measurement results of each pair of feature attributes is used to form a fuzzy equivalence matrix using closure transfer, which can further transfer and strengthen the similarity relationship between feature attributes; and, by introducing transfer rules, the direct similarity relationship can be transferred to the indirect similarity relationship through iterative application of these rules.

[0055] Specifically, during the transfer process, first define a matrix The similarity relationship on the current fuzzy similarity matrix and Multiply to continuously update the fuzzy similarity matrix, that is, integrate the new similarity relationships together. Then, from the fuzzy similarity matrix Start by finding the quadratic power (such as ), when it first appears When With transitive property, is the transitive closure of the desired , which is also the fuzzy equivalence matrix , and each element reflects the similarity between the feature attributes. Fuzzy equivalence matrix for:

[0056] ;

[0057] in, Represents the The characteristic attributes of the row and the This matrix numerically represents the similarity between the characteristic attributes of a column. This matrix covers a variety of attack type characteristics and provides a structured and quantitative representation of the similarities and correlations between characteristic attributes. It carries comprehensive information about the similarities between each characteristic attribute and provides a reference for a deeper understanding of the inherent connections between different characteristic attributes, forming the core foundation for further analysis and clustering research. By accurately quantifying the similarity between these characteristic attributes, dynamic clustering methods can more effectively identify and segment highly similar data groups.

[0058] like Figure 4 As shown, a heatmap visualizes the fuzzy equivalence matrix, providing an intuitive understanding of the relationships between the various feature attributes. The diagonal values are 1, reflecting the degree of similarity within the attribute itself. In other words, for the same feature attribute, the internal similarity is the highest. The off-diagonal positions, on the other hand, represent the similarity between different feature attributes. This similarity is based on a variety of factors, including attack characteristics, behavioral patterns, and affected systems. The value for each position is represented using fuzzy logic, ranging from 0 to 1. Values closer to 1 indicate higher similarity, while values closer to 0 indicate lower similarity. This fuzzy logic numerical representation can more accurately quantify the similarity between different feature attributes, thus playing an important role in the dynamic clustering process.

[0059] By analyzing the similarity between each characteristic attribute and other characteristic attributes, we found that these equivalence relationships exhibit diverse patterns, with some exhibiting high stability while others exhibiting significant fluctuations or variations. Analyzing these differences can provide important clues regarding characteristic attribute clustering. These clues not only help determine whether specific attributes should be grouped together, but also help understand the degree of interaction and influence between these attributes. Specifically, if certain characteristic attributes exhibit stable equivalence relationships, this typically indicates an inherent, strong correlation between these attributes, resulting in a stable and enduring relationship pattern. Such stable relationships often help identify the essential characteristics of cyberattacks or serve as key indicators in the field of network security. In contrast, characteristic attributes that exhibit significant fluctuations or variations may indicate a weaker intrinsic connection between the attributes, or that these relationships are significantly affected by external factors, such as sudden increases in network traffic, the emergence of new attack techniques, or changes in security policies.

[0060] In dynamic clustering, the fuzzy equivalence matrix Conduct detailed exploration to set several thresholds, and then further optimize the thresholds. The elements in the data are sorted from small to large and duplicates are removed, and six clear classification thresholds are obtained, namely 1.0000, 0.8561, 0.4074, 0.1586, 0.0086 and 0; then, according to the opinions and suggestions of domain experts, 0.4074 is selected as the best classification threshold. When the characteristic attributes are divided into four different categories, the first-level situation factor set can be obtained. ,in , , , They are respectively the second-level situation factor sets, such as Figure 5 As shown in Figure 2. It's important to note that the threshold setting is crucial and needs to be adjusted flexibly based on research requirements. If the threshold is set too low, multiple elements in the matrix will be close to the threshold, indicating broad similarity between feature attributes. Conversely, a higher threshold setting will result in sparse connectivity, with only a very small number of feature attributes meeting the high similarity threshold. These features are often more important and have specific meanings. Therefore, in practical applications, appropriately setting the threshold to construct the first- and second-level network situation factor sets is key to effectively reflecting network security status.

[0061] like Figure 3As shown, a fuzzy comprehensive evaluation decision model is constructed. In this embodiment, the average value of the characteristic attributes of each of the nine network attack types is extracted as the benchmark value for the seven key characteristic attributes. The characteristic attributes are refined from the diverse and complex data, thereby defining a set of representative characteristic attribute values for each network attack type, which facilitates subsequent fuzzy comprehensive evaluation and decision-making.

[0062] In the fuzzy comprehensive evaluation decision-making stage, we first determine a five-level evaluation standard based on semantic principles through a hierarchical evaluation method, providing a clear and practical guidance framework for the comprehensive evaluation of network security situation; at the same time, we ensure the orderliness and systematicness of the evaluation process and improve the interpretability and operability of the evaluation results.

[0063] In this embodiment, the network security situation assessment set [Good, Good, Average, Poor, Bad], based on the advice of experienced network security experts, the membership of each cluster's characteristic attributes to all elements in the network security situation assessment set is calculated. The value is assigned, and the range of the assigned value is required to be between 0 and 1, and the sum of the membership of the characteristic attributes of each cluster to the elements of the network security situation evaluation set is required to be 1. According to the membership of the characteristic attributes of each cluster to all elements in the network security situation evaluation set, the characteristic attribute single factor evaluation matrix is formed. , the secondary situation factors are grouped into , , , Mapped to the judgment set ;

[0064] in,

[0065] ;

[0066] ;

[0067] ;

[0068] .

[0069] In addition, in the process of network situation assessment, not all attributes contribute equally to the network situation assessment. In this embodiment, based on the advice and experience of experts in the field, the first-level situation factor set ( ) are compared with each other, and combined with Table 2 to construct the judgment matrix of the first-level situation factor set, as follows:

[0070] .

[0071] The judgment matrix for the primary situation factor set allows for a quantitative assessment of the relative importance of different situation factors. Furthermore, in establishing the judgment matrix, we prioritize the intrinsic connectivity and interaction mechanisms between factors, ensuring the rationality of the analysis. Constructing the judgment matrix is a meticulous and comprehensive process, involving a detailed assessment of the influence differences between each pair of factors, ensuring that the resulting weighting accurately reflects the actual role and importance of each factor in the cybersecurity situation assessment.

[0072] Table 2 1-9 scale table

[0073] ;

[0074] After establishing the judgment matrix, the analytic hierarchy process (AHP) is used as the main weight determination method to accurately measure the weights of the first-level situation factor set and the second-level situation factor set. First, the key eigenvalue analysis of the judgment matrix is carried out, specifically including solving the maximum eigenvalue of the judgment matrix. and its corresponding eigenvector , is the weight vector of each indicator in the factor set. It should be noted that in order to ensure the applicability of the weight vector, if the eigenvector If the sum of the elements in is not equal to 1, it needs to be normalized so that the sum of its element values reaches 1, which ensures the premise of the probability interpretation and application of the weight coefficient. In this embodiment, the maximum characteristic root of the first-level factor set judgment matrix is , and a consistency check was performed as follows:

[0075] ;

[0076] Where, is the random consistency ratio, is the consistency index of the judgment matrix, is the average random consistency index of the corresponding order. , so the judgment matrix established by the hierarchical analysis method is valid and meets the consistency. It can be seen that the weight coefficient distribution of the first-level factor set is reasonable, and its eigenvector is:

[0077] ;

[0078] Similarly, the weight coefficient of the secondary situation factor set is obtained by using the hierarchical analysis method. middle, and Each contains only one situation factor, so only Performing hierarchical analysis, we get its eigenvector as:

[0079] ;

[0080] Then use the weighted average operator to find Comprehensive evaluation matrix:

[0081] ;

[0082] because There is only one situation factor, so the comprehensive evaluation matrix is:

[0083] ;

[0084] ;

[0085] ;

[0086] In summary, the overall evaluation matrix is:

[0087] ;

[0088] Then, use the weighted average operator to calculate the weight coefficient of the first-level indicator and the overall evaluation matrix Perform operations to obtain the final fuzzy comprehensive evaluation matrix:

[0089] ;

[0090] Finally, according to the maximum membership principle, the situation value is obtained for:

[0091] ;

[0092] at this time, The "poor" element in the evaluation set corresponding to the column is in line with the actual situation of the current network security situation.

[0093] Therefore, the present invention adopts the above-mentioned network security situation assessment method that integrates fuzzy clustering analysis and fuzzy comprehensive evaluation decision-making, which can comprehensively consider the fuzzy interactions and weight distribution of each clustering factor to realize network security situation assessment, and the assessment framework is more flexible and adaptable.

[0094] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that they can still modify or replace the technical solutions of the present invention with equivalents, and these modifications or equivalent replacements cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.

Claims

1. A network security situation assessment method integrating fuzzy cluster analysis and fuzzy comprehensive evaluation decision-making is characterized by: The following steps are involved: S1. Taking the characteristic attributes of different attack types as the first-level indicator domain and the attack type as the second-level indicator trait, we can obtain the initial data matrix. S2. Use the translation-range transformation method to standardize the initial data matrix, and based on the standardized matrix, obtain the similarity measure of each pair of feature attributes through the similarity coefficient-scalar product method, and then construct the fuzzy similarity matrix; S3. Based on closure transfer, the fuzzy similarity matrix is used to obtain the fuzzy equivalence matrix, and the threshold is set by analyzing the fuzzy equivalence matrix to perform dynamic clustering, thereby constructing the first-level situation factor set and the second-level situation factor set; Dynamic clustering divides the first-level indicator domain into Divide ,in is the number of classes in dynamic clustering, and , ; The collection of clusters is the first-level situation factor set, and the characteristic attribute set in each cluster , is the set of secondary situation factors, where ; S4. Abstract the cybersecurity situation assessment scenario into a judgment set, and perform single-factor judgment on the characteristic attributes of the secondary situation factor set to obtain a single-factor fuzzy mapping set of characteristic attributes for each cluster; Among them, the single factor fuzzy mapping set is used to map the secondary situation factor set based on the advice and experience of network security experts. of The characteristic attributes of each cluster are judged by single factors, and then the characteristic attributes of each cluster are judged for the network security situation The membership degree of each element Assign values to obtain the single-factor fuzzy mapping set of characteristic attributes of each cluster , and then obtain the characteristic attribute single factor evaluation matrix of each cluster ; S5. Using the analytic hierarchy process, respectively, obtain the judgment matrices of the first-level situation factor set and the second-level situation factor set, and obtain the corresponding weight vectors according to the judgment matrices; S6. Calculate the fuzzy comprehensive evaluation matrix using a weighted average operator, and then obtain the situation value through the maximum membership principle, thereby obtaining the network security situation; Among them, the fuzzy comprehensive evaluation matrix is calculated as follows: Let the secondary situation factor set The corresponding weight vector is , using the average weighted operator and Calculate and obtain the comprehensive evaluation matrix of the characteristic attributes in each cluster: , ; Where, represents the average weighted operator; The comprehensive evaluation matrix of the characteristic attributes in each cluster is combined to obtain the total evaluation matrix: ; Similarly, obtain the first-level situation factor set The weight vector is , and then use the average weighted operator to calculate and obtain the comprehensive evaluation matrix.

2. The network security situation assessment method integrating fuzzy cluster analysis and fuzzy comprehensive evaluation decision-making according to claim 1 is characterized in that: Construct the fuzzy similarity matrix, the formula is as follows: ; in, , For the The characteristic attribute and The similarity of the feature attributes, 、 Respectively The first attack type Feature attributes, The first attack type feature attributes.

3. The network security situation assessment method integrating fuzzy cluster analysis and fuzzy comprehensive evaluation decision-making according to claim 1 is characterized in that: Obtain the fuzzy equivalence matrix, including using the fuzzy similarity matrix and solving the quadratic matrix in sequence, as follows: ; in, is the fuzzy similarity matrix, when hour, It is the fuzzy equivalence matrix.

4. The network security situation assessment method integrating fuzzy cluster analysis and fuzzy comprehensive evaluation decision-making according to claim 1 is characterized in that: The maximum membership principle includes the following steps: The situation value with the highest membership is selected to minimize the fuzziness and uncertainty of situation assessment, thereby understanding the status of network security situation.

Citation Information

Patent Citations

  • Network security prediction method based on dynamic fuzzy clustering and gray neural network

    CN112260870A

  • Hierarchical partner risk evaluation using fuzzy logic

    US20250037056A1